๐ซ๐ฎ
Shaik Sai Meera
2026-09-11 04:40:06
(1 week ago)
IM360 WAF: Hidden file access
Brute-Force
๐ซ๐ท
masterguru
2026-09-11 00:27:07
(1 week ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.94.166.25 (25.166.94.34.bc.googleuserconten ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.94.166.25 (25.166.94.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-10 10:22:40
(1 week ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
๐ง๐ช
cmbplf
2026-09-08 22:01:55
(1 week ago)
4.402 requests from abuseipdb.com blacklisted IP (8mos3w1d)
Brute-Force
Bad Web Bot
๐ฑ๐ป
garmtech.com
2026-09-08 10:17:55
(1 week ago)
Attempted access to sensitive endpoint (/.env.backup) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.env.backup) detected. Automated scan or unauthorized probing.
show less
Web App Attack
Anonymous
2026-09-08 08:38:02
(1 week ago)
34.94.166.25 - - [08/Sep/2026:08:38:01 +0000] "GET /.env.dev HTTP/1.1" 302 4951 "-" "crusader-worker ...
show more
34.94.166.25 - - [08/Sep/2026:08:38:01 +0000] "GET /.env.dev HTTP/1.1" 302 4951 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-07 08:45:42
(1 week ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-06 22:02:12
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-05.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
aks4226
2026-09-06 15:34:18
(1 week ago)
Bot search, attacking common web applications.
Web App Attack
Anonymous
2026-09-06 06:37:04
(1 week ago)
34.94.166.25 - - [06/Sep/2026:08:37:03 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 6499 "-" "crusad ...
show more
34.94.166.25 - - [06/Sep/2026:08:37:03 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 6499 "-" "crusader-worker/1.0"
34.94.166.25 - - [06/Sep/2026:08:37:03 +0200] "GET /.env.bak HTTP/1.1" 403 6499 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Anonymous
2026-09-06 04:17:27
(2 weeks ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 03:52:15
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.94.166.25 (25.166.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.166.25 (25.166.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:07.805371 2026] [security2:error] [pid 32344:tid 32344] [client 34.94.166.25:56228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.waleed-alshalan.com"] [uri "/.env.dev"] [unique_id "apzjZ0tWCPAmJlFB307-YwAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 03:32:41
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.94.166.25 (25.166.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.166.25 (25.166.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:32:33.287888 2026] [security2:error] [pid 18346:tid 18346] [client 34.94.166.25:40696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clayton.cpking.com"] [uri "/.env"] [unique_id "apze0fV3BF8F8F_Z88g4sQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:21:16
(2 weeks ago)
[dev.backorder.gr] httpd-config-scan: sites=global; logs=/var/log/nginx/access.log; samples=/.env.pr ...
show more
[dev.backorder.gr] httpd-config-scan: sites=global; logs=/var/log/nginx/access.log; samples=/.env.production | /.env.save | /.env.backup
show less
Hacking
Web App Attack
๐ฉ๐ช
sfmet-admin
2026-09-06 03:21:15
(2 weeks ago)
34.94.166.25 - - [06/Sep/2026:03:21:14 +0000] "GET /.env HTTP/2.0" 200 55 "-" "crusader-worker/1.0"
...
show more
34.94.166.25 - - [06/Sep/2026:03:21:14 +0000] "GET /.env HTTP/2.0" 200 55 "-" "crusader-worker/1.0"
...
show less
Web App Attack